Abusing an 'Intended' GraphQL API Design: A One-Click Exploit to Steal GitLab CI/CD Secrets
Nov 6, 2025 · 4 min read · Introduction Hello, I'm Adarsh Shetty, AKA Albatraoz, a Senior Appsec Engineer. By day, I secure applications and infrastructure; in my spare time, I enjoy hunting for security vulnerabilities in bug bounty programs. Over the years, my focus has grav...
Join discussion




